← Back to browse · API

CVE-2023-50564

Severity
HIGH
CVSS
8.8
EPSS
0.29069
Risk score
45.37
CISA KEV
No
PoC
No
Published
2023-12-14
Modified
2024-10-08
First seen
2026-08-07
Aliases
EUVD-2023-55346, GHSA-PHW8-53H6-PQ4G
Products
n/a:n/a n/a
Sources
euvd EUVD-2023-55346

Description

An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.

References